php.net |  support |  documentation |  report a bug |  advanced search |  search howto |  statistics |  random bug |  login
Doc Bug #60269 escapeshellcmd example is wrong; and warning should be added
Submitted: 2011-11-11 16:08 UTC Modified: 2011-12-03 06:40 UTC
From: lbarnaud@php.net Assigned: tyrael (profile)
Status: Closed Package: Documentation problem
PHP Version: Irrelevant OS:
Private report: No CVE-ID: None
Welcome back! If you're the original bug submitter, here's where you can edit the bug or add additional notes.
If you forgot your password, you can retrieve your password here.
Password:
Status:
Package:
Bug Type:
Summary:
From: lbarnaud@php.net
New email:
PHP Version: OS:

 

 [2011-11-11 16:08 UTC] lbarnaud@php.net
Description:
------------
The example on http://docs.php.net/escapeshellcmd is wrong:

<?php
// here we don't care if $e has spaces
system("echo $e");
$f = escapeshellcmd($filename);
 
// and here we do, so we use quotes
system("touch \"/tmp/$f\"; ls -l \"/tmp/$f\"");
?>

- Escapeshellcmd is meant to be used without quotes
- Adding quotes around an escaped string doesn't prevent it from being interpreted as multiple arguments by the shell:

printf('touch "/tmp/%s"', escapeshellcmd('foo" "bar'));

Result:

touch "/tmp/foo" "bar" // two arguments

The correct way of escaping an argument is to use escapeshellarg():

printf('touch /tmp/%s', escapeshellarg('foo" "bar'));

Result:

touch /tmp/'foo" "bar' // one argument

I think the second part of the example should be removed, and a warning should be added:

The string may be interpreted as multiple arguments, use escapeshellarg instead.


Related reports: https://bugs.php.net/bug.php?id=47694


Patches

Pull Requests

History

AllCommentsChangesGit/SVN commitsRelated reports
 [2011-12-03 06:40 UTC] frozenfire@php.net
-Status: Open +Status: Closed -Assigned To: +Assigned To: tyrael
 [2011-12-03 06:40 UTC] frozenfire@php.net
Tyrael fixed this bug while closing bug #60116.
 
PHP Copyright © 2001-2026 The PHP Group
All rights reserved.
Last updated: Wed Oct 07 22:00:01 2026 UTC